[Git][security-tracker-team/security-tracker][master] Update status for node-ws issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 30 08:44:25 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
62fd926d by Salvatore Bonaccorso at 2026-07-30T09:43:13+02:00
Update status for node-ws issues
CVE-2026-62389 got rejected because it is a duplicate of CVE-2026-48779.
Merge useful tracking information from CVE-2026-62389 to CVE-2026-48779.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -15209,9 +15209,6 @@ CVE-2026-62683 (File Browser is a file managing interface for uploading, deletin
NOT-FOR-US: File Browser
CVE-2026-62389
REJECTED
- - node-ws 8.21.1+~cs14.19.1-1 (bug #1142271)
- NOTE: https://github.com/websockets/ws/issues/2331
- NOTE: Fixed by: https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d (8.21.1)
CVE-2026-62378 (RustFS Console is a web management console for the RustFS distributed ...)
NOT-FOR-US: RustFS
CVE-2026-62294 (Flameshot is powerful yet simple to use screenshot software. Prior to ...)
@@ -36734,11 +36731,13 @@ CVE-2026-48782 (Pydantic AI is a Python agent framework for building application
CVE-2026-48781 (Postiz is an AI social media scheduling tool. In versions prior to 2.2 ...)
NOT-FOR-US: Postiz
CVE-2026-48779 (ws is an open source WebSocket client and server for Node.js. All vers ...)
- - node-ws 8.21.0+~cs14.19.1-1 (bug #1140429)
+ - node-ws 8.21.0+~cs14.19.1-1 (bug #1140429; bug #1142271)
[trixie] - node-ws <no-dsa> (Minor issue)
[bookworm] - node-ws <postponed> (Minor issue; memory-exhaustion DoS from a malicious peer, fixed in 8.21.0/7.5.11)
[bullseye] - node-ws <postponed> (Minor issue; memory-exhaustion DoS from a malicious peer, fixed in 8.21.0/7.5.11)
NOTE: https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p
+ NOTE: https://github.com/websockets/ws/issues/2331
+ NOTE: Fixed by: https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d (8.21.1)
CVE-2026-48777 (FileBrowser Quantum is a free, self-hosted, web-based file manager. Ve ...)
NOT-FOR-US: FileBrowser Quantum
CVE-2026-48776 (LangGraph Python SDK is used to connect to running LangGraph API serve ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62fd926de0f0ad27c4e7ca77efc49c9590ee070e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62fd926de0f0ad27c4e7ca77efc49c9590ee070e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/1b76bda4/attachment.htm>
More information about the debian-security-tracker-commits
mailing list